Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 247479 (CVE-2008-5151) - sci-visualization/mayavi symlink attack (CVE-2008-5151)
Summary: sci-visualization/mayavi symlink attack (CVE-2008-5151)
Status: RESOLVED INVALID
Alias: CVE-2008-5151
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard: ~3 [ebuild]
Keywords:
Depends on:
Blocks: debian-tempfile
  Show dependency tree
 
Reported: 2008-11-18 19:04 UTC by Stefan Behte (RETIRED)
Modified: 2009-01-20 00:15 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-11-18 19:04:16 UTC
CVE-2008-5151 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5151):
  test_parser.py in mayavi 1.5 allows local users to overwrite
  arbitrary files via a symlink attack on the /tmp/err.log temporary
  file.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-30 16:24:32 UTC
*PING*
Comment 2 Sébastien Fabbro (RETIRED) gentoo-dev 2008-12-03 15:17:26 UTC
Hi,

I think this advisory doesn't apply. The /tmp/err.log attack is on a comment in test_parser.py, and looking at the code, the only reference to a possible temp file was commented out (line 161).
So I would close this as invalid but I need security experts to confirm.

Thanks
Comment 3 Sébastien Fabbro (RETIRED) gentoo-dev 2009-01-19 22:53:07 UTC
We should close this one, as it is a non issue.
@security: ok with that?
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2009-01-20 00:15:46 UTC
Confirmed, closing.